CVE-2024-45276 describes a critical authentication bypass vulnerability affecting various Helmholz and mbCONNECT24 mbNET.mini and REX 100 devices, allowing unauthenticated remote attackers to read files within the /tmp directory. With a CVSS score of 7.5 (High), this flaw presents a low-complexity attack vector that could lead to significant information disclosure. While the vulnerability is not currently listed on CISA's KEV catalog and lacks public exploit intelligence or community discussion, organizations using affected products should prioritize patching to mitigate potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.1CPE matchmatch criteria | cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:* | ||
< 2.3.1CPE matchmatch criteria | cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.